CVE-2017-20168 MEDIUM

CVE-2017-20168: jfm-so piWallet api.php sql injection

Vendor Jfm-So
Product piWallet
Weakness CWE-89 · SQLi
Published January 11, 2023
Last update April 9, 2025

CVSS base score

5.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patch is identified as b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. It is recommended to apply a patch to fix this issue. VDB-218006 is the identifier assigned to this vulnerability.

Key dates

02Disclosure timeline

January 11, 2023 CVE published
April 9, 2025 Record updated